Privacy, cookies and analytics

What this site stores, what it sends elsewhere, and why. Written to be checkable against the running site rather than to cover us.

This page describes current behaviour in plain language. It has not been reviewed by a lawyer and is not a substitute for a formal privacy policy, which this site still needs before it takes on users at scale.

What is public by design

Reviews are public. When you publish one, the review text, your rating, the verification badge it earned, and the display name or username on your account are visible to anyone, including search engines and AI crawlers. That is the point of the site — a review nobody can read cannot help anyone.

Your email address is not shown on any public page. Wallet addresses used to prove usage are used to check the proof and are not published next to your review.

Cookies this site sets

Three, all functional, none used for advertising:

  • cc_session — keeps you signed in after you authenticate. Without it you would be signed out on every page load.
  • cc_oauth — a short-lived value during sign-in that ties the response from the identity provider back to the request that started it. It is what stops someone else’s sign-in being replayed into your browser.
  • cc_xchg — the same protection for the exchange-connection flow used to verify that you really traded on a platform.

Stored in your browser, never sent to us

  • cc-theme — light or dark.
  • cc-compare — the listings you have ticked for comparison.

Analytics

This site loads Google Tag Manager, which in turn loads Google Analytics. Google receives your IP address, the pages you visit, and the usual browser and device details, and sets its own cookies (typically _ga and _ga_…) to recognise a returning browser. We use it to see which pages people actually read.

There is no consent banner yet. Analytics currently loads for every visitor. If you are in a jurisdiction where that requires your prior consent, it is fair to say this site is not yet meeting that bar; a browser-level tracking blocker or Do Not Track extension will stop it in the meantime.

Other services your browser contacts

  • Google Fonts — the two typefaces load from Google’s servers, so Google sees your IP address on the first page you open.
  • SSOJet — handles sign-in. You authenticate on their domain and this site receives an identity claim back, not your password.
  • Cloudflare — serves the site and stores its database. Requests necessarily pass through their network.

Market data and token facts come from public sources such as CoinGecko and chain explorers. Those requests are made by our servers, not your browser, so they never see you.

What we do not do

No advertising networks, no third-party ad or retargeting pixels, and no sale of personal data. The site’s content security policy is written to permit only the Google endpoints named above, so an unexpected tracker cannot quietly load — you can check that yourself in the response headers.

Deleting your data

Ask and we will remove your account and reviews. There is no self-serve delete button yet; that is a gap, not a policy.

How scoring works →